01-31-2019 11:56 AM - edited 03-08-2019 05:13 PM
Hi,
I have registered the license on new catalyst 9300 model using smart license manager portal. Now it is not possible to connect the switch again to internet or to use proxy methods to send license usage . I am not using any DNA product in my environment. So only using routing and switching part.
My question is , what is going to happen ? Is the switch going to continue working properly ?
Regards,
01-31-2019 12:32 PM
Hi,
Is the switch going to continue working properly ?
Yes, the switch will work with no issues. You don't have to be connected to the Internet.
HTH
02-01-2019 01:38 AM
Thanks a lot Reza for reply ! I need to deploy couple of distribution switches in other locations and I was doubting about license issue thinking of ordering other type or other vendor. Now I will go ahead and deploy CAT9Ks
02-01-2019 06:56 AM
You should be fine. With licenses, as long as they are valid, usually, you configure and apply it once. The license stays the same even with IOS upgrades.
Good Luck!
04-08-2019 01:09 PM
Hi Reza
in the similar situation of having no DNA etc advantage stuff i cant see _basic_ licensing on the Cat9300 switch :0)
could u please advice where to look/dig? :0)
evaluation (hopefuly only DNA stuff) will expire in few days (i'm on the deployment for few days meantime :0).
i'm interesting only in IBNS 2.0 full feature-set.
Fuji 16.9.2
Technology Package License Information:
------------------------------------------------------------------------------
Technology-package Technology-package
Current Type Next reboot
------------------------------------------------------------------------------
network-advantage Smart License network-advantage
dna-advantage Subscription Smart License dna-advantage
#sho license all
Smart Licensing Status
======================
Smart Licensing is ENABLED
Registration:
Status: UNREGISTERED
Export-Controlled Functionality: Not Allowed
License Authorization:
Status: EVAL MODE
Evaluation Period Remaining: 7 days, 18 hours, 55 minutes, 35 seconds
Export Authorization Key:
Features Authorized:
<none>
Utility:
Status: DISABLED
Data Privacy:
Sending Hostname: yes
Callhome hostname privacy: DISABLED
Smart Licensing hostname privacy: DISABLED
Version privacy: DISABLED
Transport:
Type: Callhome
License Usage
==============
(C9300-48 Network Advantage):
Description:
Count: 1
Version: 1.0
Status: EVAL MODE
Export status: NOT RESTRICTED
(C9300-48 DNA Advantage):
Description:
Count: 1
Version: 1.0
Status: EVAL MODE
Export status: NOT RESTRICTED
Product Information
===================
UDI: PID:C9300-48P,SN:FCW2244E11Y
Agent Version
=============
Smart Agent for Licensing: 4.5.6_rel/12
Component Versions: SA:(1_3_dev)1.0.15, SI:(dev22)1.2.1, CH:(rel5)1.0.3, PK:(dev18)1.0.3
Reservation Info
================
License reservation: DISABLED
11-25-2019 09:56 PM
Hi All,
We need to get our new Cisco 9300s connect to the internet to register smart licensing.
Please send a url or document on how to get the switch connect to the internet.
Thank you in advance
11-26-2019 03:20 AM
Hi,
You just have to allow HTTP/HTTPS on the firewall for a L3 interface on the switch to be able to get internet access and communicate with cisco smart portal. You should also have an account on cisco smart portal, and switch license should be placed on that portal (where you will have to generate a registration key).
Please follow these steps for license registration :
Kind regards,
Mohamed Hawas
11-26-2019 08:26 PM
Hi Mohamed,
what is the IP add of the Cisco Smart Portal?
Can you ping the Cisco portal add to prove that the switch have internet access?
Thanks
11-27-2019 12:43 AM
As mentioned in the document , you will have to connect to CSSM by configuring this URL on the switch
https://tools.cisco.com/its/service/oddce/services/DDCEService
Yes, you can ping the domain to test conenctivity
ping tools.cisco.com
Pinging tools.cisco.com [173.37.145.8] with 32 bytes of data:
Reply from 173.37.145.8: bytes=32 time=134ms TTL=240
Reply from 173.37.145.8: bytes=32 time=135ms TTL=240
Reply from 173.37.145.8: bytes=32 time=134ms TTL=240
Reply from 173.37.145.8: bytes=32 time=133ms TTL=240
You can use firmware release Fuji-16.8.1a if you don't want Smart license registration and use RTU instead
03-21-2019 02:57 PM
11-27-2019 10:10 AM
Mohamed,
I see that most of the people have addressed your query. I would like to add my 2 cents to it and I hope this will be informative.
Once the device is registered it communicates to the Smart Account every 30 days. In case it fails then the device will generate error as shown below.
%SMART_LIC-3-COMM_FAILED: Communications failure with the Cisco Smart Software Manager or satellite: Fail to send out Call Home HTTP message.
Once the device is not been able to communicate with the Cisco Smart Account associated for over 90 days then it will generate error as shown below and the license state will change to "Authorization Expired".
%SMART_LIC-3-AUTH_RENEW_FAILED: Authorization renewal with the Cisco Smart Software Manager or satellite: Communication message send error for udi PID:XXX, SN: XXX
Even after switch enters into Authorization Expired state there will be no functional impact or disruption (no impact to any L2 or L3 features ), even after reload. There is no enforcement in place.
Regards,
Vivek Sharma
12-06-2019 01:36 AM - edited 12-06-2019 03:36 AM
We have a customer who for their accreditation must authenticate all internet access. They do this using a proxy. I can configure the call-home and http client on the switch to use a proxy, however it appears the switch doesn't support authentication:
In global configuration you can configure the http client username & password (ip http client username, ip http client password), would these help or is this for something else?
The customer can allow temporary exceptions in their proxy, but they can't be permanent. Is this functionality in the road-map?
12-06-2019 03:03 AM
Hi Andy
ip http client has exactly the purpose u need. other Q is does it work :0)
12-06-2019 04:28 AM - edited 12-06-2019 04:28 AM
Hi Andy
The documentation specifically states that it doesn't support authenticated HTTPs proxy: [quote]Authenticated HTTPs proxy configurations are not supported. [/quote]
So is this incorrect? Would adding the 'ip http client username xxx & ip http client password xxx' work in this case to provide credentials to the proxy server?
12-06-2019 05:13 AM
Hi Andy
as per doc it wont work unless u are allowed to authenticate on proxy with HTTP only; u have to consult proxy-admin on this option;
if it wont be the option request customer to setup internal satellite server; on the satellite's external connection to proxy u will be able authenticate with HTTPS
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide